Fake Recruiters Steal Corporate Logins on Mobile

Help Net Security · Medium sophistication
Last updated August 26, 2026

Scammers posing as HR staff at major brands are luring targets into an interview “scheduling” flow that ultimately steals corporate passwords on mobile devices. The campaign uses a browser-in-the-browser style approach (or a full-screen fake login on phones) and even blocks personal email logins to focus only on high-value corporate accounts.

Key findings

  • Scammers impersonate HR/recruiters and use interview scheduling as the lure to capture corporate passwords.
  • On mobile, the kit uses a full-screen fake login (no address bar) to remove easy legitimacy checks.
  • The phishing kit filters out personal email addresses and only allows corporate credentials to proceed.
  • Zimperium tracked brand-impersonation domains for a year and found common hosting/ASN patterns, frequently involving AWS and SEDO GmbH.
  • The campaign impersonates a wide range of brands across multiple industries.

Who’s being targeted

  • Commonly targeted roles: All employees, HR/Recruiting, Executives, IT/Identity & Access Management, Mobile device users.
  • Affected industries: E-commerce, Luxury goods, Aviation, Retail, Professional services.
  • Attack channels: website.
  • Impersonated: HR staff at a well-known company (recruiting team).

Awareness takeaways

  • Treat unsolicited interview/scheduling links as high-risk, verify the recruiter and company using a trusted channel before signing in.
  • Be extra cautious with mobile logins: a full-screen sign-in page can hide key trust signals, making fake login pages harder to detect.
  • If a page refuses personal email and insists on corporate credentials, assume it may be targeting enterprise access and stop to verify.
  • Warn staff about brand lookalike domains (e.g., “-careers” / “-global”) and encourage reporting quickly, since blocklists may lag.

Red flags to watch for

  • Login page is full-screen on mobile with no visible address bar to verify the real site
  • Site blocks personal email accounts and insists on corporate credentials
  • Lookalike domains that mimic brands (e.g., “[company]-careers.com”)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a text or email from “HR” at a big-name company: “Interview scheduling request, please sign in to confirm your availability.” You tap the link on your phone and it opens a full-screen login. No browser frame, no address bar, just a page asking for your corporate email and password on something like “acme-careers.com.” This is a mobile browser-in-the-browser style scam built to steal corporate logins. Here’s the sneaky part: type a personal Gmail or Outlook address and the site rejects it. Only your corporate account is allowed through. Zimperium found these fake HR sites running for months on common hosts like AWS, using lookalike domains like “-careers” and “-global” to reel people in. If any interview link on your phone opens a full-screen login and refuses personal email, stop. Don’t sign in there, contact the recruiter or company using a known email or phone number and confirm it first.

Similar attacks

Fake Recruiters Steal Enterprise Logins on Mobile

Fake Recruiters Steal Enterprise Logins on Mobile

A real “fake recruiter” phishing campaign (tracked as RecruitTrap) is targeting employees’ corporate credentials, especially on mobile devices. The scam uses lookalike recruitment domains and full-screen fake login pages that hide browser cues, and it rejects personal email addresses to focus on…

August 25, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment failed” billing email to drive victims to a credit-card theft page. The report also notes other brand-impersonation scams using cloned stores…

July 24, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
AI “Apple Support” Calls Steal Passcodes & 2FA

AI “Apple Support” Calls Steal Passcodes & 2FA

Researchers uncovered a phishing-as-a-service platform (“AnonyMousKIT”) used by phone thieves to trick victims into handing over iPhone passcodes, Apple ID passwords, and live 2FA codes so thieves can remove Apple’s Activation Lock. The operation uses Apple-branded emails/pages and AI voice agents…

August 26, 2026